Linux Kernel Race Condition Vulnerability

cve CVE-2025-39964 3 sources, 3 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Linux Kernel Race Condition Vulnerability Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations … the claim
Severity
MEDIUM NVD
moderate Red Hat
CVSS they disagree
5.5 NVD
7.3 Red Hat
Exploited
yes CISA Known Exploited Vulnerabilities
Known ransomware campaign use
Unknown CISA Known Exploited Vulnerabilities
Due date
2026-09-21 CISA Known Exploited Vulnerabilities
Vendor
Linux CISA Known Exploited Vulnerabilities
Linux NVD
Product
Kernel CISA Known Exploited Vulnerabilities
Linux NVD
CWE
CWE-362 CISA Known Exploited Vulnerabilities
CWE-362 NVD
CWE-366 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild · CISA Known Exploited Vulnerabilities 2026-09-18
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVlocal Llocal L
Attack complexity AClow Llow L
Privileges required PRlow Llow L
User interaction UInone Nnone N
Scope Sunchanged Uunchanged U
Confidentiality Cnone Nhigh H
Integrity Inone Nlow L
Availability Ahigh Hhigh H

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2025-10-13first spoke of it: Linux Kernel Race Condition VulnerabilityNVD
2025-10-13first spoke of it: kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsgRed Hat
2026-09-18first spoke of it: Linux Kernel Race Condition VulnerabilityCISA Known Exploited Vulnerabilities
2026-09-21Due dateCISA Known Exploited Vulnerabilities

What it is to other things

affectslinux/linux_kernel
NVD
affectssiemens/simatic_s7-1500_cpu_1518-4_pn\/dp_mfp
NVD
affectssiemens/simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
NVD
affectssiemens/simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp
NVD
affectssiemens/simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware
NVD
made_bylinux
NVD
made_bysiemens
NVD

In words only, so not counted until a person confirms one:

affectslinux/kernel
CISA Known Exploited Vulnerabilities says “Linux · Kernel”
affectslinux/linux
NVD says “Linux · Linux”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD5.5
receipt
Source
NVD
Its words
5.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC5.5
2026-09-29 09:45 UTC7.8
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat7.3
receipt
Source
Red Hat
Its words
7.3
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-39964",
  "CWE": "CWE-366",
  "advisories": [
    "RHSA-2026:71592",
    "RHSA-2026:71594",
    "RHSA-2026:73788",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:70498",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:70402",
    "RHSA-2026:71601",
    "RHSA-2026:70459",
    "RHSA-2026:71657",
    "RHSA-2026:70403",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:5.14.0-687.50.1.el9_8",
    "kernel-0:6.12.0-211.58.1.el10_2",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:6.12.0-259.27.el10nv",
    "kernel-0:4.18.0-553.166.1.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:4.18.0-477.170.1.el8_8",
    "kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-0:4.18.0-372.218.1.el8_6",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2"
  ],
  "bugzilla": "2403545",
  "bugzilla_description": "kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
  "cvss3_score": "7.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-10-13T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-39964.json",
  "severity": "moderate"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2025-39964",
  "CWE": "CWE-366",
  "advisories": [
    "RHSA-2026:71592",
    "RHSA-2026:71594",
    "RHSA-2026:73788",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:70498",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:70402",
    "RHSA-2026:71601",
    "RHSA-2026:70459",
    "RHSA-2026:71657",
    "RHSA-2026:70403",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:5.14.0-687.50.1.el9_8",
    "kernel-0:6.12.0-211.58.1.el10_2",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:6.12.0-259.27.el10nv",
    "kernel-0:4.18.0-553.166.1.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:4.18.0-477.170.1.el8_8",
    "kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-0:4.18.0-372.218.1.el8_6",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2"
  ],
  "bugzilla": "2403545",
  "bugzilla_description": "kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
  "cvss3_score": "7.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-10-13T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-39964.json",
  "severity": "moderate"
}
—
CWE
cwe
different words
CISA Known Exploited VulnerabilitiesCWE-362
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-362
Read by
field:cwes
Said since
2026-10-06 12:19 UTC
Last answered
2026-10-06 16:31 UTC
2026-10-06 12:19 UTCCWE-362
2026-09-28 11:44 UTC—
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
CWE
cwe
different words
NVDCWE-362
receipt
Source
NVD
Its words
CWE-362
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-362
2026-10-06 11:54 UTCCWE-362, CWE-362
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-366
receipt
Source
Red Hat
Its words
CWE-366
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-39964",
  "CWE": "CWE-366",
  "advisories": [
    "RHSA-2026:71592",
    "RHSA-2026:71594",
    "RHSA-2026:73788",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:70498",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:70402",
    "RHSA-2026:71601",
    "RHSA-2026:70459",
    "RHSA-2026:71657",
    "RHSA-2026:70403",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:5.14.0-687.50.1.el9_8",
    "kernel-0:6.12.0-211.58.1.el10_2",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:6.12.0-259.27.el10nv",
    "kernel-0:4.18.0-553.166.1.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:4.18.0-477.170.1.el8_8",
    "kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-0:4.18.0-372.218.1.el8_6",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2"
  ],
  "bugzilla": "2403545",
  "bugzilla_description": "kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
  "cvss3_score": "7.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-10-13T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-39964.json",
  "severity": "moderate"
}
—
CWES
cwes
CISA Known Exploited VulnerabilitiesCWE-362
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-362
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-09-21
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-09-21
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Exploitation
exploitation
NVDactive
Reliable evidence that it is exploited in the wild.
receipt
Source
NVD
Its words
active
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCactive
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiestrue
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Yes
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Packages
packages
Red Hatkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:5.14.0-687.50.1.el9_8, kernel-0:6.12.0-211.58.1.el10_2, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:6.12.0-259.27.el10nv, kernel-0:4.18.0-553.166.1.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:3.10.0-1160.164.1.el7, kernel-0:4.18.0-477.170.1.el8_8, kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10, kernel-0:5.14.0-427.152.1.el9_4, kernel-0:4.18.0-372.218.1.el8_6, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2
receipt
Source
Red Hat
Its words
kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:5.14.0-687.50.1.el9_8, kernel-0:6.12.0-211.58.1.el10_2, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:6.12.0-259.27.el10nv, kernel-0:4.18.0-553.166.1.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:3.10.0-1160.164.1.el7, kernel-0:4.18.0-477.170.1.el8_8, kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10, kernel-0:5.14.0-427.152.1.el9_4, kernel-0:4.18.0-372.218.1.el8_6, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2
Read by
field:affected_packages[]
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:5.14.0-687.50.1.el9_8, kernel-0:6.12.0-211.58.1.el10_2, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:6.12.0-259.27.el10nv, kernel-0:4.18.0-553.166.1.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:3.10.0-1160.164.1.el7, kernel-0:4.18.0-477.170.1.el8_8, kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10, kernel-0:5.14.0-427.152.1.el9_4, kernel-0:4.18.0-372.218.1.el8_6, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2
2026-09-29 09:44 UTCkernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:5.14.0-687.50.1.el9_8, kernel-0:6.12.0-211.58.1.el10_2, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:4.18.0-553.166.1.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:3.10.0-1160.164.1.el7, kernel-0:4.18.0-477.170.1.el8_8, kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10, kernel-0:5.14.0-427.152.1.el9_4, kernel-0:4.18.0-372.218.1.el8_6, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2
What the source handed over
{
  "CVE": "CVE-2025-39964",
  "CWE": "CWE-366",
  "advisories": [
    "RHSA-2026:71592",
    "RHSA-2026:71594",
    "RHSA-2026:73788",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:70498",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:70402",
    "RHSA-2026:71601",
    "RHSA-2026:70459",
    "RHSA-2026:71657",
    "RHSA-2026:70403",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:5.14.0-687.50.1.el9_8",
    "kernel-0:6.12.0-211.58.1.el10_2",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:6.12.0-259.27.el10nv",
    "kernel-0:4.18.0-553.166.1.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:4.18.0-477.170.1.el8_8",
    "kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-0:4.18.0-372.218.1.el8_6",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2"
  ],
  "bugzilla": "2403545",
  "bugzilla_description": "kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
  "cvss3_score": "7.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-10-13T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-39964.json",
  "severity": "moderate"
}
—
Product
product
different words
CISA Known Exploited VulnerabilitiesKernel
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Kernel
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Product
product
different words
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
medium
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-39964",
  "CWE": "CWE-366",
  "advisories": [
    "RHSA-2026:71592",
    "RHSA-2026:71594",
    "RHSA-2026:73788",
    "RHSA-2026:71687",
    "RHSA-2026:72059",
    "RHSA-2026:70498",
    "RHSA-2026:71565",
    "RHSA-2026:71326",
    "RHSA-2026:70402",
    "RHSA-2026:71601",
    "RHSA-2026:70459",
    "RHSA-2026:71657",
    "RHSA-2026:70403",
    "RHSA-2026:71569",
    "RHSA-2026:71327",
    "RHSA-2026:71606"
  ],
  "affected_packages": [
    "kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7",
    "kernel-0:5.14.0-687.50.1.el9_8",
    "kernel-0:6.12.0-211.58.1.el10_2",
    "kernel-0:4.18.0-305.209.1.el8_4",
    "kernel-0:6.12.0-259.27.el10nv",
    "kernel-0:4.18.0-553.166.1.el8_10",
    "kernel-0:6.12.0-55.106.1.el10_0",
    "kernel-0:3.10.0-1160.164.1.el7",
    "kernel-0:4.18.0-477.170.1.el8_8",
    "kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10",
    "kernel-0:5.14.0-427.152.1.el9_4",
    "kernel-0:4.18.0-372.218.1.el8_6",
    "kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2",
    "kernel-0:5.14.0-570.143.1.el9_6",
    "kernel-0:6.12.0-231.20.el10nv",
    "kernel-0:5.14.0-284.194.1.el9_2"
  ],
  "bugzilla": "2403545",
  "bugzilla_description": "kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg",
  "cvss3_score": "7.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-10-13T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-39964.json",
  "severity": "moderate"
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
CISA Known Exploited VulnerabilitiesLinux
receipt
Source
CISA Known Exploited Vulnerabilities
Last answered
2026-10-06 16:31 UTC
What the source handed over
{
  "cveID": "CVE-2025-39964",
  "cwes": "CWE-362",
  "dateAdded": "2026-09-18",
  "dueDate": "2026-09-21",
  "forensicTriage": "Yes",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
  "product": "Kernel",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Race Condition Vulnerability"
}
—
Vendor
vendor
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "9aee87da5572b3a14075f501752e209801160d3d",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "45bcf60fe49b37daab1acee57b27211ad1574042",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              },
              {
                "lessThan": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
                "status": "affected",
                "version": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "crypto/af_alg.c",
              "include/crypto/if_alg.h"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "2.6.38"
              },
              {
                "lessThan": "2.6.38",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.245",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.194",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.154",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.108",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.49",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.16.*",
                "status": "unaffected",
                "version": "6.16.9",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.17",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "cisaActionDue": "2026-09-21",
    "cisaExploitAdd": "2026-09-18",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Linux Kernel Race Condition Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
                "versionEndExcluding": "5.10.245",
                "versionStartIncluding": "2.6.38",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
                "versionEndExcluding": "5.15.194",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
                "versionEndExcluding": "6.1.154",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
                "versionEndExcluding": "6.6.108",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
                "versionEndExcluding": "6.12.49",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
                "versionEndExcluding": "6.16.9",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
                "matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
                "matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
                "matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
                "matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
                "matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
                "versionStartIncluding": "3.1.6",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg\n\nIssuing two writes to the same af_alg socket is bogus as the\ndata will be interleaved in an unpredictable fashion.  Furthermore,\nconcurrent writes may create inconsistencies in the internal\nsocket state.\n\nDisallow this by adding a new ctx->write field that indiciates\nexclusive ownership for writing."
      }
    ],
    "id": "CVE-2025-39964",
    "lastModified": "2026-09-19T04:17:48.307",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-39964",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-18T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-13T14:15:34.737",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-362"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Linux Kernel Race Condition Vulnerability
zetlyn/cve-kev · 2026-09-18
cwe CWE-362 cwes CWE-362 due_date 2026-09-21 exploited yes forensic_triage true known_ransomware_campaign_use Unknown product Kernel vendor Linux
kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
zetlyn/cve-redhat · 2025-10-13
cvss 7.3 cvss_vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H cwe CWE-366 packages kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:5.14.0-687.50.1.el9_8, kernel-0:6.12.0-211.58.1.el10_2, kernel-0:4.18.0-305.209.1.el8_4, kernel-0:6.12.0-259.27.el10nv, kernel-0:4.18.0-553.166.1.el8_10, kernel-0:6.12.0-55.106.1.el10_0, kernel-0:3.10.0-1160.164.1.el7, kernel-0:4.18.0-477.170.1.el8_8, kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10, kernel-0:5.14.0-427.152.1.el9_4, kernel-0:4.18.0-372.218.1.el8_6, kernel-rt-0:5.14.0-284.194.1.rt14.479.el9_2, kernel-0:5.14.0-570.143.1.el9_6, kernel-0:6.12.0-231.20.el10nv, kernel-0:5.14.0-284.194.1.el9_2 severity moderate source
Linux Kernel Race Condition Vulnerability
zetlyn/cve-nvd · 2025-10-13
automatable no cvss 5.5 cvss_vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H cwe CWE-362 exploitation active product Linux severity MEDIUM status Analyzed technical_impact total vendor Linux source